Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The README instructs users to place a Google OAuth client secret and long-lived refresh token in environment variables without any guidance on secure storage, scope minimization, or avoiding accidental exposure in shell history, process listings, logs, or CI environments. While environment variables are sometimes used operationally, presenting this as the default setup for sensitive credentials increases the risk of credential leakage and unauthorized access to GA4 data.
